Windows 10 forgotten password (Off VPN)

%3CLINGO-SUB%20id%3D%22lingo-sub-2556849%22%20slang%3D%22en-US%22%3EWindows%2010%20forgotten%20password%20(Off%20VPN)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2556849%22%20slang%3D%22en-US%22%3E%3CP%3ESo%20straight%20to%20the%20problem%2C%20the%20relaxed%20user%20comes%20back%20off%20holiday%20and%20typically%20has%20forgotten%20their%20password.%20They%20cannot%20logon%20to%20there%20hybrid%20laptop%20and%20due%20to%20the%20lack%20of%20an%20always-on-VPN%20will%20now%20need%20to%20drive%20into%20the%20office%20so%20they%20can%20connect%20to%20the%20network%20and%20cache%20a%20new%20password%20which%20has%20been%20set%20from%20them.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThe%20user%20could%20logon%20locally%20with%20an%20emergency%20account%20and%20a%20unique%20password%2C%20An%20analyst%20could%20then%20assist%20them%20with%20the%20built%20in%20Windows%2010%20Quick%20Assist%20application%20and%20enable%20the%20required%20VPN%20in%20a%20different%20session.%20This%20is%20not%20a%20very%20elegant%20solution%20and%20would%20need%20a%20way%20to%20centrally%20manage%20that%20password%20and%20audit%20it's%20use.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EI'm%20sure%20someone%20else%20has%20come%20across%20this%20especially%20now%20we%20have%20more%20home%20workers%2C%20ideas%20here%20please%2C%20anything%20greatly%20appreciated.%3CBR%20%2F%3E%3CBR%20%2F%3EAn%20additional%20thought%2C%20perhaps%20a%20Cisco%20AnyConnect%20VPN%20Management%20Tunnel%20on%20the%20ASA%20might%20give%20the%20PC%20access%20to%20the%20DC%20pre-logon%20so%20if%20the%20password%20was%20reset%20in%20AD%20then%20the%20users%20PC%20would%20cache%20that%20and%20permit%20them%20to%20logon%2C%20just%20a%20thought.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Senior Member

So straight to the problem, the relaxed user comes back off holiday and typically has forgotten their password. They cannot logon to there hybrid laptop and due to the lack of an always-on-VPN will now need to drive into the office so they can connect to the network and cache a new password which has been set from them.


The user could logon locally with an emergency account and a unique password, An analyst could then assist them with the built in Windows 10 Quick Assist application and enable the required VPN in a different session. This is not a very elegant solution and would need a way to centrally manage that password and audit it's use.


An additional thought, perhaps a Cisco AnyConnect VPN Management Tunnel on the ASA might give the PC access to the DC pre-logon so if the password was reset in AD then the users PC would cache that and permit them to logon, just a thought.

An alternative might be the Start Before Logon (SBL) feature which starts a VPN connection before the user logs in to Windows. This ensures that users connect to their corporate infrastructure before logging on to their computers.
On Windows, the Pre-Login Access Provider (PLAP) is used to implement AnyConnect SBL.

With PLAP, the Ctrl+Alt+Del key combination opens a window where the user can choose either to log in to the system or activate Network Connections (PLAP components) using the Network Connect button in the lower-right corner of the window.

This permits the user to connect into the Active Directory infrastructure by being able to communicate with the domain controller.

I'm sure someone else has come across this especially now we have more home workers, ideas here please, anything greatly appreciated.



0 Replies